CVE-2007-1923
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
(1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control lists by changing the set of URLs linked from menus, which allows remote attackers to access restricted functionality via direct requests. The LedgerSMB affected versions are before 1.3.0.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.59% probability · 84th percentile
- CISA KEV
- Not listed
- Affected
- ledgersmb/ledgersmb · sql-ledger/sql-ledger
- Source
- cve@mitre.org
References
- http://osvdb.org/38217Broken Link
- http://osvdb.org/38218Broken Link
- http://securityreason.com/securityalert/2552Third Party Advisory
- http://www.securityfocus.com/archive/1/464880/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23352Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33494Third Party Advisory, VDB Entry
- https://github.com/ledgersmb/LedgerSMB/blob/master/ChangelogRelease Notes
- http://osvdb.org/38217Broken Link
- http://osvdb.org/38218Broken Link
- http://securityreason.com/securityalert/2552Third Party Advisory
- http://www.securityfocus.com/archive/1/464880/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23352Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33494Third Party Advisory, VDB Entry
- https://github.com/ledgersmb/LedgerSMB/blob/master/ChangelogRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.